Search CVE reports


Toggle filters

31 – 40 of 52 results


CVE-2020-10134

Medium priority
Vulnerable

Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairing devices via adjacent access when the unauthenticated user initiates different pairing methods in each peer...

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2020-0556

Medium priority
Fixed

Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Fixed
Show less packages

CVE-2019-8922

Medium priority
Fixed

A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of...

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Not affected Not affected Not affected Fixed
Show less packages

CVE-2019-8921

Medium priority
Fixed

An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning...

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-10910

Low priority

Some fixes available 1 of 6

A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any...

2 affected packages

bluez, gnome-bluetooth

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Ignored
gnome-bluetooth Fixed
Show less packages

CVE-2017-13220

Medium priority
Fixed

An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.

24 affected packages

bluez, linux, linux-aws, linux-azure, linux-euclid...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Not affected
linux Not affected
linux-aws Not affected
linux-azure Not affected
linux-euclid Not in release
linux-flo Not in release
linux-gcp Not affected
linux-gke Not in release
linux-goldfish Not in release
linux-grouper Not in release
linux-hwe Not affected
linux-hwe-edge Fixed
linux-kvm Not affected
linux-lts-trusty Not in release
linux-lts-utopic Not in release
linux-lts-vivid Not in release
linux-lts-wily Not in release
linux-lts-xenial Not in release
linux-maguro Not in release
linux-mako Not in release
linux-manta Not in release
linux-oem Not affected
linux-raspi2 Not affected
linux-snapdragon Not affected
Show all 24 packages Show less packages

CVE-2017-1000250

High priority
Fixed

All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory....

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez
Show less packages

CVE-2016-9918

Negligible priority
Vulnerable

In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9917

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2016-9804

Negligible priority
Vulnerable

In BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because "commands" array is overflowed by supplied parameter due to lack of boundary checks on size of...

1 affected package

bluez

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bluez Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages